Privacy policy
PRIVACY POLICY
Last updated: 1 March 2026
Frøken Lilly (“we”, “us”, “our”) is the data controller for the processing of personal data collected via this website and related services (the “Services”), which are provided through Shopify.
This Privacy Policy explains how we collect, process, store, and disclose personal data when you visit the website, make a purchase, or communicate with us.
If there is any conflict between our Terms of Service and this Privacy Policy, this Privacy Policy shall prevail with respect to the processing of personal data.
1. Personal Data We Collect
“Personal Data” means any information that directly or indirectly identifies you or can reasonably be linked to you.
We may collect the following categories of Personal Data:
Contact Information:
Name
Address
Shipping and billing address
Phone number
Email address
Financial Information:
Payment card details (processed exclusively by payment providers)
Transaction and Order Information:
Payment confirmations
Payment method
Shopping cart and wishlist
Purchased, returned, and exchanged products
Order history
Account Information:
Username
Password (encrypted)
Preferences and settings
Communications:
Customer service inquiries
Emails and messages sent to us
Device and Usage Information:
IP address
Browser and device data
Network information
Clicks, views, and traffic history
2. How We Collect Information
We collect information directly from you when you place an order, create an account, contact us, or otherwise use our Services.
We also collect information automatically through cookies and Shopify technologies.
In addition, we may receive information from service providers and partners, including payment providers, shipping partners, marketing platforms, and Shopify.
3. Purposes and Legal Basis for Processing
A) Performance of Contract
We process Personal Data to handle orders, process payments, deliver products, manage returns, and handle complaints.
Legal basis: GDPR Article 6(1)(b) (performance of a contract).
B) Customer Service
We process Personal Data to respond to inquiries and provide support.
Legal basis: GDPR Article 6(1)(b) and 6(1)(f) (legitimate interest).
C) Marketing and Profiling
We use cookies and similar technologies to display relevant advertisements, perform segmentation, analyze and optimize marketing activities, and measure campaign performance.
This may include processing IP addresses, device information, behavioral data, purchase history, and email addresses (for newsletters and custom audiences).
We use, among others:
Google (Google Ads and Analytics)
Meta Platforms (Facebook and Instagram)
TikTok
Pinterest
Email marketing platforms
Legal basis: GDPR Article 6(1)(a) (consent).
You may withdraw your consent at any time via cookie settings or the unsubscribe link in marketing emails.
D) Security and Fraud Prevention
We process Personal Data to prevent misuse and protect our webshop.
Legal basis: GDPR Article 6(1)(f) (legitimate interest).
E) Accounting and Bookkeeping
We process Personal Data to comply with accounting and tax legislation.
Legal basis: GDPR Article 6(1)(c) (legal obligation).
4. Disclosure of Personal Data
We may disclose Personal Data to:
Shopify (hosting and technical operations)
Payment providers
Shipping companies
Accounting systems and auditors
IT and email service providers
Marketing platforms
Shipping companies and payment providers act as independent data controllers.
Other suppliers may act as data processors with whom we have entered into data processing agreements.
5. Relationship with Shopify
Our webshop is hosted by Shopify, which may process Personal Data as part of providing and operating the platform.
Shopify may act as an independent data controller for certain processing activities, including the use of global infrastructure and enhanced platform features.
Shopify’s Privacy Policy is available at:
https://privacy.shopify.com/da
6. International Transfers
Personal Data may be transferred to countries outside the EU/EEA, including the United States.
Transfers take place based on:
European Commission Standard Contractual Clauses (SCCs), and/or
The EU-U.S. Data Privacy Framework, where applicable.
7. Retention and Deletion
We retain Personal Data only for as long as necessary for the relevant purpose.
Accounting records are retained for 5 years in accordance with Danish bookkeeping law.
Purchase data is retained for up to 5 years.
Complaint cases are retained for up to 3 years from the date of purchase.
Newsletter data is retained until consent is withdrawn. If no activity (such as opens or clicks) has occurred for a continuous period of up to 24 months, the data will be automatically deleted.
Customer inquiries are generally deleted no later than 12 months after completion.
User accounts are deleted after 24 months of inactivity.
Server logs are retained for 6–12 months.
Personal Data may be retained longer if necessary to establish, exercise, or defend legal claims.
8. Your Rights
Under applicable data protection law, you have the right to:
Access your Personal Data
Rectify inaccurate data
Request erasure
Restrict processing
Object to processing
Data portability
Withdraw consent at any time
To exercise your rights, please contact us.
You may lodge a complaint with the Danish Data Protection Agency:
www.datatilsynet.dk
9. Children
The Services are not directed at individuals under the age of 18.
10. Changes
We may update this Privacy Policy from time to time. The date at the top indicates the latest revision.
11. Contact Information
Frøken Lilly
Email: contact@frokenlilly.dk
Address: Fyrrevænget 16, 3630 Jægerspris, Denmark
CVR: 45782158